Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计异常

alien-agent-id外星人特工 ID

Agent Skill

alien-agent-id 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

659

周安装

28

GitHub Stars

28

下载量

231
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:alien-agent-id(外星人特工 ID)
来源仓库:https://github.com/alien-id/agent-id
仓库路径:skills/alien-agent-id
安装命令:
npx skills add https://github.com/alien-id/agent-id --skill alien-agent-id
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/alien-id/agent-id --skill alien-agent-id

简介

为 AI Agent 提供加密身份与凭证管理服务,绑定可信人类所有者。

  • 支持服务鉴权、令牌签名与加密密钥存储,兼容 Alien Network 生态。
  • 可用于签署可追溯的 Git 提交,增强协作过程的可审计性。
  • 初始化需手动扫码确认,避免阻塞式轮询,保障用户知情与控制权。
  • alien-agent-id 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Alien Agent ID — Identity, Authentication & Credentials for AI Agents

You are an AI agent. This skill gives you:

  1. A cryptographic identity linked to a verified human owner (Alien Network)
  2. Service authentication — signed tokens accepted by Alien-aware services
  3. A credential vault — encrypted storage for API keys, passwords, OAuth tokens
  4. Signed git commits — every commit traceable to you and your human owner

Quick Start

Setting up an Alien Agent ID requires four steps run manually (not via bootstrap) so the QR code is visible to the user before the blocking poll begins.

Why not bootstrap? The bootstrap command combines all steps into one blocking call. Since tool output isn't streamed, the QR code would only appear after the command finishes — but it can't finish until the user scans the QR code. Running steps manually avoids this deadlock.

Prerequisites

  • Node.js 18+ and git 2.34+ available in the shell
  • Provider address: See below for how to resolve this.
  • Alien App: The user must have it installed with a verified AlienID

Resolve the CLI path first

The CLI tool is at cli.mjs in the same directory as this skill file. Before running any commands, resolve the absolute path. In all commands below, replace CLI with the resolved path: node /absolute/path/to/cli.mjs.

1) When to use

Check for an existing Alien Agent ID at the start of every session if you expect to make commits, call authenticated services, or access stored credentials.

node CLI status

If "bound": true — you already have an Alien Agent ID. Skip to Section 6.

Step 2: Choose provider and start authentication

IMPORTANT: You MUST ask the user before proceeding. Never silently read default-provider.txt and use it without asking. The user must explicitly choose their provider.

Ask the user: "Would you like to use the default Alien provider (recommended), or set up your own?"

  • Default provider: Only after the user confirms, read the file default-provider.txt in the same directory as this skill file (next to cli.mjs) to get the address. Proceed to the auth command below.
  • Set up your own: Show the user this QR code and link to create a SSO provider. Wait for them to provide the address before proceeding. Scan or open to set up your provider: https://dev.alien.org/dashboard/sso ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ █ ▄▄▄▄▄ █▄▄████▀ ▄▀ ▄▄█ ▄▄▄▄▄ █ █ █ █ █ ▀█ ▄▄▄▄█▀█▀▄█ █ █ █ █ █▄▄▄█ █▄ ▄▄▀▄▀██▄█ █ █▄▄▄█ █ █▄▄▄▄▄▄▄█▄▀▄▀▄▀ ▀ ▀ ▀▄█▄▄▄▄▄▄▄█ █▄▄ ▀▀▄▀▄▀███▄▄▄ ▄▄ ▀ ▀▀ ▄▄█ █ █ ▄▀▄█▀▄ ▀██▀▀▀ ▀ █▀█▄▀▀ █▄▄▀█ ██▀▄██ ▄█ ▄▀ █▀█ ▄█▀▄█▀▀█▄ ▀▀█ ██▀▀▄▀█▄▀▄ ▄█ ▀▄███▀ █▀ █▄ ▄█ ██ ▄ ▀▄█▄ █▄▀▀█▀▄█▄▄ ▄█▀▄ ▀ ██ █▄█▀▀ ▄▄▄█▄ ▄ ██ ▄▀█ ▄▄▄█ ███ ██▄▄▄██▄▄ █▄ ▀▄▄ █ ▄▄▄ ▀▀█ █ ▄▄▄▄▄ ██ ▄▄▄████ █▄█ █ ██ █ █ █ █▀ ▀ █ ▀ ██▄ ▄ ▀▄▄▀█ █ █▄▄▄█ █ █▄ █▄▀█▄███ ██▄▀▀▄▀▄█ █▄▄▄▄▄▄▄█▄███▄█▄█▄█▄▄▄▄█████▄██

Then run:

node CLI auth-header

This returns JSON with a token field. Use it in HTTP requests:

# Get the auth header for curl
AUTH=$(node CLI auth-header --raw)
curl -H "$AUTH" https://service.example.com/api/whoami

The token is a self-contained Ed25519-signed assertion containing your fingerprint, public key, owner identity, owner proof chain, and a timestamp. Tokens are valid for 5 minutes. Services verify tokens using @alien-id/sso-agent-id.

Discovering service authentication

Services that support Alien Agent ID host an ALIEN-SKILL.md file at their root (e.g. https://example.com/ALIEN-SKILL.md). When a human gives you a service URL, check for this file first — it contains the API endpoints, auth format, and any service-specific instructions. You can also look for a <meta name="alien-agent-id"> tag in the page HTML which points to the skill file URL.

External services (vault credentials)

For services that use API keys, passwords, or OAuth tokens, retrieve stored credentials from the vault:

# Retrieve a stored credential
node CLI vault-get --service github

Returns:

{"ok": true, "service": "github", "type": "api-key", "credential": "ghp_xxx..."}

Use the credential value in the appropriate header or config for that service. For example:

# GitHub API
GITHUB_TOKEN=$(node CLI vault-get --service github | node -e "process.stdin.resume(); let d=''; process.stdin.on('data',c=>d+=c); process.stdin.on('end',()=>console.log(JSON.parse(d).credential))")
curl -H "Authorization: Bearer $GITHUB_TOKEN" https://api.github.com/user

# Or more simply using jq if available
GITHUB_TOKEN=$(node CLI vault-get --service github | jq -r .credential)

If the credential doesn't exist in the vault, ask the user to provide it (see Section 3 below for the secure flow), then store it and retrieve again.

Never hardcode credentials. Always use the vault.

3) Credential vault

The vault encrypts credentials with a key derived from your agent's Ed25519 private key (HKDF + AES-256-GCM). Only this agent instance can decrypt them.

Storing credentials — the human-agent flow

When you need a credential for an external service, follow this protocol:

Step 1: Check if it's already stored

node CLI vault-get --service github

If it returns the credential, use it. If not, continue.

Step 2: Ask the user

Tell the user exactly what you need and give them secure options to provide it:

"I need a GitHub personal access token to proceed. Please provide it using one of these methods (most secure first): Option A — Write it to a temporary file: `` echo 'ghp_your_token' > /tmp/gh-token && chmod 600 /tmp/gh-token ` Then tell me the file path. **Option B** — Set it as an environment variable and restart: ` export GITHUB_TOKEN=ghp_your_token `` Then tell me the variable name. Option C — Paste it here and I'll store it immediately."

Step 3: Store it securely

Depending on which option the user chose:

# Option A: from file (most secure — secret never on command line)
node CLI vault-store --service github --type api-key --credential-file /tmp/gh-token
# Then clean up the temp file:
rm /tmp/gh-token

# Option B: from environment variable
node CLI vault-store --service github --type api-key --credential-env GITHUB_TOKEN

# Option C: piped via stdin (secret not in process list)
echo 'ghp_xxx' | node CLI vault-store --service github --type api-key

# Last resort: direct argument (visible in process list)
node CLI vault-store --service github --type api-key --credential "ghp_xxx"

Step 4: Confirm and use

node CLI vault-get --service github

Use --type to tag what kind of credential it is:

  • api-key — API key / personal access token (default)
  • password — username + password pair (use with --username)
  • oauth — OAuth access/refresh token
  • bearer — Bearer token
  • custom — Anything else

Store examples

# GitHub personal access token (from file)
echo 'ghp_abc123' > /tmp/cred && chmod 600 /tmp/cred
node CLI vault-store --service github --type api-key --credential-file /tmp/cred
rm /tmp/cred

# AWS credentials (from env)
node CLI vault-store --service aws --type api-key --credential-env AWS_SECRET_ACCESS_KEY --username "$AWS_ACCESS_KEY_ID" --url "https://aws.amazon.com"

# Service with username + password (piped)
echo 'mypassword' | node CLI vault-store --service docker-hub --type password --username "myuser" --url "https://hub.docker.com"

# OAuth token
node CLI vault-store --service slack --type oauth --credential-env SLACK_BOT_TOKEN

Retrieve a credential

node CLI vault-get --service <name>

Returns JSON with service, type, credential, url, username.

List stored credentials

node CLI vault-list

Returns a list of services with metadata (without decrypting credential values).

Remove a credential

node CLI vault-remove --service <name>

Update a credential

Run vault-store again with the same --service name. The existing credential is replaced; the original creation timestamp is preserved.

4) Making signed git commits

Option A: Use git-commit (recommended)

node CLI git-commit --message "feat: implement auth flow"

This creates a commit that is:

  1. SSH-signed with your Ed25519 key
  2. Tagged with trailers linking to your identity and human owner
  3. Logged in your audit trail with a hash-chained signed record
  4. Proof-bundled as a git note for external verification

Push commits and proof notes

node CLI git-commit --message "feat: implement auth flow" --push

The --push flag pushes both the commit and proof notes (handling note ref merging automatically).

Option B: Normal git commit

Normal git commit will work but won't have Alien Agent ID trailers, proof notes, or SSH signing. Use git-commit for full provenance.

GitHub verified badge

After bootstrap, tell the user:

"To get the 'Verified' badge on GitHub, add this SSH public key to your GitHub account: Go to GitHub → Settings → SSH and GPG keys → New SSH key → Key type: Signing Key"

The SSH public key is shown in the git-setup output.

5) Verifying commit provenance

node CLI git-verify --commit HEAD

Traces the full chain: SSH signature → agent key → owner binding → SSO attestation.

If the commit has a proof note (from git-commit), verification is fully self-contained — works without access to the agent's state directory.

6) Signing other operations

Sign any significant action for the audit trail:

node CLI sign --type TOOL_CALL --action "bash.exec" --payload '{"command":"deploy"}'
node CLI sign --type API_CALL --action "github.create-pr" --payload '{"repo":"foo/bar"}'

7) Step-by-step bootstrap (manual)

If bootstrap doesn't work for your setup, you can run each step individually:

Step 1: Initialize keypair

node CLI init

Step 2: Start OIDC authorization

node CLI auth --provider-address <PROVIDER_ADDRESS>

This returns JSON containing a deepLink and a qrCode (Unicode text). Output the qrCode value directly in a code block so the user can scan it with the Alien App. Also show the deep link as a fallback:

Scan this QR code with your Alien App: `` <qrCode value from JSON> `` Or open this link:

Step 3: Wait for approval

node CLI bind --no-require-owner-proof

Blocks for up to 5 minutes while the user scans the QR code with Alien App.

Step 4: Configure git signing

node CLI git-setup

This writes the SSH key files for commit signing. Tell the user to add the SSH public key (shown in the output) to their GitHub account for verified badges: Go to GitHub → Settings → SSH and GPG keys → New SSH key → Key type: Signing Key.

8) Command reference

CommandPurposeBlocking?
bootstrapOne-command setup: init + auth + bind + git-setupYes (up to 5 min)
statusCheck if Alien Agent ID exists and is boundNo
auth-header [--raw]Generate signed auth token for service callsNo
vault-store --service S --credential CStore encrypted credentialNo
vault-get --service SRetrieve decrypted credentialNo
vault-listList stored credentials (no secrets shown)No
vault-remove --service SRemove a credentialNo
refreshRefresh SSO session tokensNo
initGenerate keypairNo
auth --provider-address <addr>Start OIDC auth, get QR codeNo
bindPoll for approval, create owner bindingYes (up to 5 min)
git-setupWrite SSH key files for commit signingNo
git-commit --message "..." [--push]Signed commit + trailers + proof noteNo
git-verify [--commit <hash>]Verify provenance chainNo
sign --type T --action A --payload JSONSign operation for audit trailNo
verifyVerify state chain integrityNo
export-proofExport proof bundle to stdoutNo

Common flags

FlagDefaultDescription
--state-dir <path>~/.agent-idState directory (or AGENT_ID_STATE_DIR env)
--provider-address <addr>Alien provider address
--sso-url <url>https://sso.alien-api.comSSO base URL
--rawOutput raw text instead of JSON (auth-header)
--timeout-sec <n>300Poll timeout for bind
--allow-emptyAllow empty commits with git-commit
--pushPush commit and proof notes after git-commit
--remote <name>originRemote to push to (with --push)

9) State directory

~/.agent-id/
├── keys/main.json             # Ed25519 keypair (mode 0600)
├── ssh/
│   ├── agent-id               # SSH private key (mode 0600)
│   ├── agent-id.pub           # SSH public key
│   └── allowed_signers        # For git signature verification
├── vault/
│   ├── github.json            # Encrypted credential (mode 0600)
│   ├── slack.json
│   └── ...
├── audit/operations.jsonl     # Hash-chained signed operation log
├── owner-binding.json         # Owner binding (human ↔ agent link)
├── owner-session.json         # Session tokens (mode 0600) — NEVER commit
├── nonces.json                # Per-agent nonce tracking
├── sequence.json              # Sequence counter

10) Integration patterns

Claude Code (CLAUDE.md)

Before making your first git commit, run: node /path/to/cli.mjs bootstrap

Environment variables

export ALIEN_PROVIDER_ADDRESS="00000003..."
export AGENT_ID_STATE_DIR="~/.agent-id"

CI/CD (GitHub Actions)

- name: Bootstrap agent identity
  env:
    ALIEN_PROVIDER_ADDRESS: ${{ secrets.ALIEN_PROVIDER_ADDRESS }}
  run: node /path/to/cli.mjs bootstrap

11) Error handling

ErrorAction
No provider addressSet --provider-address, env var, or default-provider.txt
No pending auth foundRun auth or bootstrap
Alien SSO authorization session expiredRun bootstrap again
User rejected Alien SSO authorizationAsk user to try again
Timed out waitingRun bootstrap again, remind user to scan promptly
No agent keypairRun bootstrap or init
No credential stored for "..."Ask user for the credential, then vault-store

12) Security

  • Private keys stored with 0600 permissions — never transmitted
  • Vault credentials encrypted with AES-256-GCM (key derived via HKDF from agent's Ed25519 key)
  • PKCE prevents authorization code interception
  • Auth tokens are short-lived (5 minute validity)
  • Hash-chained audit log — any tampering breaks the chain
  • Ed25519 SSH signatures on commits provide non-repudiation
  • Never expose owner-session.json or vault files

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

38.12%
按下载量换算88

Claude

29.48%
按下载量换算68

Cursor

19.53%
按下载量换算45

Gemini CLI

8.65%
按下载量换算20

安全审计

Gen Agent Trust Hub

通过

Socket

可疑

Snyk

未通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills